Headers:
Message body:
From: {random email}
Subject: {random}
hiAttached to the email is a Zip file (Note: filename is random}
Here is a document that you asked
Inside the Zip file is a Windows Executable file:
scan 59334.zip
Sha256 Hashes:
scan 59334.scr
2191354418154983ab885cc8063bd5c9a50bda057794c61ee7556930e4f33fbb [1]
Malware Anti-Virus Reports:
VirusTotal Report: [1] (hits 2/57 Virus Scanners)
Malwr Report: [1]
Summary:
Creates a windows hook that monitors keyboard input (keylogger)
Creates Zeus (Banking Trojan) mutexes
Creates an Alternate Data Stream (ADS)
Installs itself for autorun at Windows startup
Cheers,
Steve
Sanesecurity.com
No comments:
Post a Comment